CVE-2026-66494
JoomShaper · SP Page Builder extension for Joomla
The SP Page Builder extension for Joomla is vulnerable to improper access control and cross-site scripting, allowing unauthenticated attackers to potentially impact system integrity.
Executive summary
A critical vulnerability in the JoomShaper SP Page Builder extension for Joomla enables unauthenticated attackers to bypass access controls and potentially execute malicious scripts.
Vulnerability
This vulnerability involves improper access control (CWE-284) and improper neutralization of input (CWE-79), which can be triggered by an unauthenticated attacker through the web interface.
Business impact
The flaw carries a CVSS score of 8.7, reflecting a high potential for total impact on system availability, integrity, and confidentiality. Successful exploitation could lead to unauthorized administrative actions, defacement, or the theft of sensitive session data, posing a significant risk to the security posture of the host Joomla site.
Remediation
Immediate Action: Administrators must update the SP Page Builder extension to the latest available version provided by JoomShaper to remediate the access control and input validation flaws.
Proactive Monitoring: Review web server and Joomla audit logs for suspicious requests targeting extension endpoints, particularly those originating from unknown or unauthorized IP addresses.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block malicious input patterns and restrict access to administrative extension paths.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the severity of the vulnerability and the potential for unauthenticated exploitation, immediate action is required. Organizations should verify their current version of SP Page Builder and apply the vendor-supplied patch as soon as possible to prevent potential compromise of their web infrastructure.